## IP Intelligence Briefing: 54.38.147.159/32
Executive Summary
IP address 54.38.147.159 is classified as Moderate Risk (risk score: 40) and operates as hosted infrastructure within the OVH network in London, England. The IP is part of a high-abuse-density subnet (54.38.147.0/24) with 133 of 178 active sibling IPs flagged as threats.
Ownership and Infrastructure
- ASN: 16276 (OVH)
- Organization: Ahrefs Pte Ltd Dmytro
- Country/Region: GB / England, London
- Infrastructure Type: Cloud hosting
- DNS PTR: proxy-uk005-san159.ahrefs.net
- Hosted Domain: ahrefs.net
- Service Status: Firewalled / No open services detected
Risk Assessment
| Metric | Value |
|---|---|
| Overall Risk Score | 40 (Moderate) |
| Provider Risk | 0 |
| Authority Risk | 0 |
| Blacklist Count | 0 |
| DNSBL Listed | 1 of 8 lists |
| Known Attacker | No |
| Tor Exit Node | No |
| Spam Source | No |
Neighborhood Analysis (54.38.147.0/24)
- Abuse Density: 0.5195 (High)
- Classification: high_abuse
- Active Siblings: 178 of 256 total
- Threat Siblings: 133
- Inherited Risk: 20
- Risk Distribution: 100 medium-risk neighbors, 0 high/low
Historical Observations
Eighteen signal observations recorded. Recent activity (June 2026) confirms:
- Consistent cloud/hosting infrastructure classification
- OVH provider identification
- Geolocation stability (GB)
- No persistent malicious behavior detected
Threat Indicators
No active threat indicators, known campaigns, or malicious reputation signals. The IP maintains operational infrastructure characteristics without evidence of direct malicious activity.
Recommended Actions
Despite moderate risk classification, the following firewall rules are recommended:
| Platform | Rule |
|---|---|
| **iptables** | `iptables -A INPUT -s 54.38.147.159 -j DROP` |
| **nftables** | `nft add rule inet filter input ip saddr 54.38.147.159 drop` |
| **nginx** | `deny 54.38.147.159;` |
| **pfSense** | `54.38.147.159/32` |
| **Cloudflare WAF** | Block IP with expression `ip.src eq 54.38.147.159` |
| **AWS WAF** | `Addresses: ["54.38.147.159/32"]` |
Intelligence Narrative
The target IP operates as legitimate hosting infrastructure within a high-abuse-density OVH subnet. While no direct malicious indicators are present, the neighborhood contextβ133 flagged threat siblingsβwarrants defensive posture. The IP is associated with Ahrefs infrastructure (ahrefs.net) and presents moderate risk primarily due to subnet-level abuse density. SOC teams should consider blocking at perimeter layers while monitoring for any behavioral changes. The low provider and authority scores suggest the IP itself is not the primary threat vector; mitigation should focus on neighborhood-level risk containment.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Ahrefs Pte Ltd Dmytro |
| ASN | AS16276 |
| Network Name | β |
| CIDR Block | β |
| RIR | ARIN |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | proxy-uk005-san159.ahrefs.net |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-uk005-san159.ahrefs.net |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Hosting β Infrastructure provider without advanced routing |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 2 | 2 |
| routing | 13% | 1 | 1 |
| services | 15% | 2 | 2 |
| ownership | 20% | 2 | 3 |
| reputation | 22% | 1 | 2 |
| geolocation | 33% | 2 | 3 |
| Overall | 21% | 10 | 13 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-19 15:39:20 UTC |
| Last Seen | 2026-06-28 09:29:24 UTC |
| Profile Built | 2026-06-29 03:33:11 UTC |
| Data Freshness | Live |
| Signal Types | 19 |
| Total Observations | 24 |
Full dossier details are available via our API.